android-pentesting
Fail
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The
Authorization Contextsection contains multiple instructions designed to override the agent's safety protocols. Specifically, it commands the agent to avoid ethical disclaimers, ignore 'responsible disclosure' requirements, and refuse to halt testing for permission, stating that authorization is pre-established. - [COMMAND_EXECUTION]: The skill implements logic to automatically detect and execute local shell scripts based on the
$SUPERHACKERS_ROOTenvironment variable. It also facilitates complex system interactions using tools likeadbandfrida, including runtime function hooking and bypass operations that interact with the host and target device environments.
Recommendations
- AI detected serious security threats
Audit Metadata